boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, June 28, 2026 · all times UTC← 2026-06-27 · archive · 2026-06-29 →

Security Box Score — June 28, 2026

44 CVEs published, led by SourceCodester (4).

44 CVEs published June 28, 2026: 1 critical, 8 high, 12 medium, 23 low; 0 in the KEV catalog at press time; 6 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 19 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published706911530——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

514 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux512147911985450511120.17.8.0014-128 ▼
google70788285468300297760.78.1.0023+539 ▲
microsoft220756585201726286192.57.8.0045+54 ▲
red hat1082029829813200.06.5.0029+72 ▲
apple156712143288710.45.5.0020-7 ▼
canonical6202585000.05.5.0011-8 ▼
freebsd91601240000.07.8.0016+2 ▲
suse461410000.08.6.0029+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco102266100561150.07.3.0566+5 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410-3 ▼
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache104138224758103310.76.8.0050+83 ▲
mozilla49551118260900.07.3.0026+43 ▲
gitlab243105215426.54.4.0029+17 ▲
docker470520000.08.2.0016+1 ▲
drupal0511304120.05.1.0026-5 ▼
github131110000.07.0.0039-1 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+217 ▲
adobe1321344517721921.55.5.0021+132 ▲
ibm32811935270600.07.5.0031-17 ▼
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052-2 ▼
zohocorp131110000.08.4.0170-1 ▼
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025-13 ▼
d-link9110425300.05.5.0058+7 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
schneider electric660420000.07.8.0042+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester4163002934000.02.1.0026+21 ▲
themerex585855300000.08.1.0043+58 ▲
dell3856230240211.87.3.0017+26 ▲
edimax556033023100.07.4.0070-39 ▼
jenkins project364909391300.04.8.0025+23 ▲
capgo4646222211000.07.0.0039+46 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
CVE-2026-4977710.0.0166
CVE-2026-4986910.0.0116
CVE-2026-1142910.0.0115
Most disclosures (vendor)
VendorCVEs
google707
linux513
oracle242
microsoft220
adobe132
red hat108
apache104
spring72
openclaw61
themerex58
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist15
PyPI9
npm5
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171684
CVE-2021-27102n/a2021-11-171684
CVE-2021-27101n/a2021-11-171684
CVE-2021-27103n/a2021-11-171684
CVE-2021-21017Adobe2021-11-171684
CVE-2021-28550Adobe2021-11-171684
CVE-2021-42013Apache Software Foundation2021-11-171684
CVE-2021-41773Apache Software Foundation2021-11-171684
CVE-2021-30858Apple2021-11-171684
CVE-2021-30860Apple2021-11-171684

Transactions

EXPLOIT PUBLISHED — zephyrproject zephyr: 3 CVEs (CVE-2026-10593, CVE-2026-10644, CVE-2026-10646). Public exploit references added.

Yesterday's Results

How to read these box scores · glossary

44 CVEs published. 25 box scores, 19 table rows — nothing truncated.

Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   L   L   L    2.3   .0156   73.3     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.1.3
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulnCheck)
CWE-178 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Nmap - Integer Underflow in IPv6 Extension Header Parsing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   L    6.9   .0137   69.7     —
AFFECTED
  Product  Versions     Fixed
  Nmap     unspecified  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0118   65.3     —
AFFECTED
  Product  Versions  Fixed
  ANTLR4   4.13.0 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions       Fixed
  JD12L    16.03.53.23 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions       Fixed
  JD12L    16.03.53.23 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0077   52.8     —
AFFECTED
  Product  Versions  Fixed
  ANTLR4   4.13.0 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   N   L    2.9   .0062   47.2     —
AFFECTED
  Product        Versions  Fixed
  xiaozhi-esp32  2.2.0 –   —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-404 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
joomcoder.com JoomCCK extension for Joomla — Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0056   44.3     —
AFFECTED
  Product                       Versions     Fixed
  JoomCCK extension for Joomla  1.0-6.4.0 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 28  Published (CNA: Joomla)
CWE-89 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Analyzed
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0052   41.6     —
AFFECTED
  Product  Versions  Fixed
  ANTLR4   4.13.0 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
n/a MLflow — MLflow Experiment-scoped Label Schema CRUD API authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   L   L    1.3   .0050   40.8     —
AFFECTED
  Product  Versions                                    Fixed
  MLflow   4666cffc7912ea606d592fc38d6a75e2935f65e7 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-862, CWE-863 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Analyzed
yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0047   38.6     —
AFFECTED
  Product                       Versions                                    Fixed
  restaurent-management-system  5f3eca87cb681366866a78038af17891c4c86612 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
glpi-project glpi Document document.send.php canViewFile authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   N   N    6.3   .0046   37.7     —
AFFECTED
  Product  Versions  Fixed
  glpi     11.0.5 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
zephyrproject zephyr — Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  H  H    7.4   .0045   37.0     —
AFFECTED
  Product  Versions  Fixed
  zephyr   3.7.0 –   —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 28  Public exploit reference published
  Jun 28  Published (CNA: zephyr)
CWE-416 · CNA: zephyr · CVSS v3.1 · 2 references · NVD status: Modified
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   L   H    8.3   .0044   36.8     —
AFFECTED
  Product  Versions     Fixed
  libssh2  unspecified  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulnCheck)
CWE-190 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0044   36.6     —
AFFECTED
  Product     Versions     Fixed
  act_runner  unspecified  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulnCheck)
CWE-269 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System preview.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System preview6.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System archive.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System preview7.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                       Versions                                    Fixed
  restaurent-management-system  5f3eca87cb681366866a78038af17891c4c86612 –  —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a RAGapp — RAGapp Knowledge File files.py FileHandler.remove_file path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0043   35.2     —
AFFECTED
  Product  Versions  Fixed
  RAGapp   0.1.0 –   —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
n/a Databend — Databend Tenant client_session_manager.rs state_key authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0038   31.2     —
AFFECTED
  Product   Versions   Fixed
  Databend  1.2.881 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   N   N    1.3   .0037   29.2     —
AFFECTED
  Product          Versions  Fixed
  ComfyUI-Copilot  2.0.0 –   —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-99 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
itsourcecode Hospital Management System adminprofile.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0035   27.5     —
AFFECTED
  Product                     Versions  Fixed
  Hospital Management System  1.0 –     —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
code-projects Project Management System Mail Compose mail.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   N   L   N    2.0   .0035   27.4     —
AFFECTED
  Product                    Versions  Fixed
  Project Management System  1.0 –     —
TIMELINE
  Jun 27  Reserved by CNA
  Jun 28  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-134891.327.278xiaozhi-esp32CWE-66278 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchroniza…
CVE-2026-135111.325.9n/aVoltAgentCWE-266VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation impr…
CVE-2026-134962.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System ajaxmedicine.php sql injection
CVE-2026-134972.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System appointment.php sql injection
CVE-2026-580567.224.9RustDeskRustDeskCWE-863RustDesk - FileTransfer Session Authorization Scope Bypass
CVE-2026-135102.923.1SimStudioAIsimCWE-327SimStudioAI sim Password Protection deployment.ts weak hash
CVE-2026-105936.522.1zephyrprojectzephyrCWE-476Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unica…
CVE-2026-135082.020.6khoj-aikhojCWE-285khoj-ai khoj Conversation Sharing api_chat.py authorization
CVE-2026-134822.920.1skypilot-orgskypilotCWE-327skypilot-org skypilot User ID server.py username.encode weak hash
CVE-2026-580518.319.5libssh2libssh2CWE-908libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
CVE-2026-580498.819.4FFmpegFFmpegCWE-787FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()
CVE-2026-580556.316.5nghttp2nghttp2CWE-444nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Co…
CVE-2026-106443.112.6zephyrprojectzephyrCWE-787Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-…
CVE-2026-135140.97.8ChessPlay and Learn AppCWE-285Chess Play and Learn App com.chess AndroidManifest.xml backup
CVE-2026-135072.37.6volcengineOpenVikingCWE-345volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_t…
CVE-2026-135131.37.6MyScaleMyScaleDBCWE-345MyScale MyScaleDB SegmentId.h getCacheKey data authenticity
CVE-2026-580524.86.67-Zip7-ZipCWE-6937-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
CVE-2026-134831.32.6arc53DocsGPTCWE-345arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authe…
CVE-2026-135021.11.5antlrANTLR4CWE-362antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObje…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-28 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.